MGUxMGM3NjQ5YTRlY2U1YWU4OGZlYzU3NDcyYWUwN2Y5ZjM2NzI4YWEzNDc2MGFlZTc0MjcwNDBjMGRhMWM3OA.msfhae0t.eyJ1cmwiOiIvcGwvY291cnNlX2luc3RhbmNlLzIvaW5zdGFuY2VfcXVlc3Rpb24vMjA5LyIsImF1dGhuX3VzZXJfaWQiOiIxIn0
Skip to main content Accessibility guide
PrairieLearn Go home
  • XC 101, SectionA
  • Assessments
  • Gradebook
  • C4
Load from disk
  • Dev User student
    View type
    ✓ Staff view staff ✓ Student view student ✓ Student view without access restrictions student
    Effective user
    Customize…
    Course Requests Settings Log out

Regenerate assessment instance

Warning: Regenerating the assessment instance will select a new set of questions from this assessment. Any progress on the current assessment instance will be lost.

Are you sure you want to regenerate the assessment instance?

Course staff: Regenerate your assessment instance to pick up changes to the assessment or to get a fresh set of questions.

C4.38. Element pl-xss-safe: present potentially malicious student code

Questions below were designed to showcase the different features of pl-xss-safe. The goal of pl-xss-safe is to allow instructors to display to students formatted HTML with potentially malicious source, such as student-submitted content.


The typical use of this element would be to provide, in the submission panel, a formatted view of a student's HTML or Markdown code. In that case, a pl-file-editor or pl-file-upload element provides the interface for the user to input the code in the question panel, while the same file name is used in the pl-xss-safe element to identify the file.

What is the meaning of life?

ans1.html
Editor Settings

The element pl-xss-safe can also be used to format Markdown code by using language="markdown".

Note that the preview attribute of pl-file-editor also provides a similar functionality in the question panel, and also provides the same XSS filtering functionality as pl-xss-safe.

What is the meaning of life?

ans2.md
Editor Settings
Preview

The element pl-xss-safe also supports content that does not come from a file, using the contents attribute. A typical use-case for this processing is when a regular element is used that does not save its content in a file, such as a pl-string-input. In that case, contents="" provides the content to be displayed.

Provide the input This is a **bold** text to make the word bold.

Additional attempts available with new variants

Correct answer

Collection 4

Assessment overview
Total points: 0/360
Score:
0%

Question C4.38

All variants: Open (current)
Total points: — /2
Manually-graded question

This form is only for reporting errors in the question itself. Do not use this form if you just don't know how to answer the question.

Previous question Next question

 Personal Notes

No attached notes

Attached files will be saved here for your reference. These files act as personal notes and can be used for your own review purposes. They are not used for grading.

Max file size: 10 MB

Attached personal notes will be saved here for your reference. These notes can be used for your own review purposes. They are not used for grading.

Staff information

Student details

Dev User
dev@example.com

Question

QID:
element/xssSafe
Title:
Element pl-xss-safe: present potentially malicious student code

Variant

Started at:
2026-08-04 16:37:34 (CDT)
Duration:
0s
Show/Hide answer
{}

Assessment instance

Assessment:
gallery/elements
Started at:
2026-08-04 16:37:17 (CDT)
Duration:
0s
View log
This box is not visible to students.